Sec Bug->Req #78305 [Dup]: Injection of INI settings into FPM worker processes

From: Date: Sat, 04 Dec 2021 18:27:07 +0000
Subject: Sec Bug->Req #78305 [Dup]: Injection of INI settings into FPM worker processes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-238174@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78305&edit=1 ID: 78305 Updated by: bukka@php.net Reported by: mp at webfactory dot de Summary: Injection of INI settings into FPM worker processes Status: Duplicate -Type: Security +Type: Feature/Change Request Package: FPM related Operating System: Ubuntu 18.04.2 LTS PHP Version: 7.1.30 Block user comment: N Private report: Y New Comment: This behaviour is on purpose and its mitigation (optional disabling) is treated as a feature. Previous Comments: ------------------------------------------------------------------------ [2019-08-14 05:53:38] stas@php.net Duplicate of bug #77190 ------------------------------------------------------------------------ [2019-07-17 10:08:19] mp at webfactory dot de Description: ------------ Dear Security team, I am not familiar with reporting security issues and hope that this is the right way to report it, to make it helpful to you and that you share my assessment. The underlying issue has been known for more than 8 years: https://bugs.php.net/bug.php?id=53611 The problem is that if you're able to access the unix socket and/or network port for a particular PHP-FPM pool, you can use the "PHP_VALUE" variable to send ini settings (including PHP_INI_SYSTEM) to the FPM worker process. This setting *will persist* beyond the single request - that is, it will affect requests and scripts executed by the particular worker process. You could, for example, configure an auto_prepend_file and so effectively be able to run code during the subsequent request served by the FPM worker process. For shared hosting environments, the recommendation probably is to have different PHP-FPM pools per vhost. But as long as the unix and/or network socket can be accessed by users or code from other vhosts, this bug is probably an issue. I don't know if it is reliably possible to limit unix domain socket or even network port access for PHP scripts? I mean, if I can run a script in one virtual host, I can probably access all network ports, even if FPM is bound to 127.0.0.1? Thanks for your time and patience! -mp. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78305&edit=1

« previous php.bugs (#238174) next »